Gravity SMTP Security Breach CVE‑2026‑4020 Exposes API Keys
Patch Gravity SMTP to version 2.1.5 or later immediately to fix CVE‑2026‑4020 and rotate any exposed API keys.
Patch Gravity SMTP to version 2.1.5 or later immediately and rotate any exposed API keys.
Summary
Gravity SMTP, a paid plugin for Gravity Forms, released version 2.1.5 with security enhancements. The update patches CVE‑2026‑4020, a vulnerability that exposed a mock‑data API endpoint. The endpoint dumps all plugin settings, including API keys, and was present in earlier versions. The changelog did not disclose the severity of the exploit, which caused a SendGrid account to be closed due to leaked keys. The plugin’s security breach was discovered by a user who noticed the vulnerability. The CVE allows attackers to read sensitive configuration data. The plugin’s developers recommend updating to 2.1.5 or later immediately. Users should also rotate any compromised API keys.
Key changes
- Gravity SMTP 2.1.5 patches CVE‑2026‑4020 vulnerability.
- CVE exposed mock‑data API endpoint that dumps plugin settings and API keys.
- Changelog omitted severity disclosure of the exploit.
- SendGrid account closed due to leaked API keys from the vulnerability.
- Users must rotate compromised API keys after patching.